TCP/IP content filtering will not be resisted by a normal HTTP proxy as the keywords will still
be present when communicating with the proxy server. However, encrypted proxy servers
may be used to hide what is being accessed through them.
Server takedown, Denial of Service, and domain deregistration are more difficult to resist
and require effort on the part of the service operator rather than those who access the Web
site. Moving the service to a different location is comparatively easy, as is changing the domain name—particularly if the service has planned for this possibility. More difficult is to notify
their users of the new address before the attack is repeated.
Reliability
Even where users are not attempting to circumvent the system, they may still be able to access the prohibited resource. Provided they are implemented correctly and the hardware is
capable of handling the required processing, all except Denial of Service and social techniques will block all accesses. The problem with Denial-of-Service attacks is that when
systems are overloaded, they will drop some requests at random. This results in some connections, which the censor intended to block, getting through. With social techniques, if someone is simply unaware of the risks they may visit the banned site regardless.
Organizations implementing technical filtering systems must also build a list of sites and
pages to block. This is a considerable undertaking if the content to be blocked is a type
of content, such as pornography, rather than a specific site, such as an opposing political
party. There are commercial filtering products that contain a regularly updated list of material
commonly objected to, but even this is likely to miss significant content. Keyword filtering
(whether at TCP/IP packet level or by HTTP proxy) mitigates this partially, as only the prohibited keywords need to be listed, rather than enumerating all sites that contain them, but sites
aware of this technique can simply not use the offending keyword and select an equivalent
term.
Cost and Speed
The cost of deploying a filtering mechanism depends on the complexity of the hardware
required to implement it. Also, due to the limited market, specialized Internet filtering equipment is comparatively expensive, so if general purpose facilities can be used to implement
filtering, the cost will be lower.
Both of these factors result in TCP/IP header filtering being the cheapest option available.
Routers already implement logic for redirecting packets based on destination IP address and
adding so-called null routing entries, which discard packets to banned sites, is fairly easy.
However, routers can only handle up to a maximum number of rules at a time, so this could
become a problem in routers working near their limit. Adding port numbers to these rules
requires some additional facilities within the router, but as only the header needs to be
inspected, the speed penalty of enabling this is small.
68
Steven J. Murdoch and Ross Anderson
Précédent

- 85/467

Suivant